WO2022037509A1 - 一种接入控制方法及装置 - Google Patents

一种接入控制方法及装置 Download PDF

Info

Publication number
WO2022037509A1
WO2022037509A1 PCT/CN2021/112662 CN2021112662W WO2022037509A1 WO 2022037509 A1 WO2022037509 A1 WO 2022037509A1 CN 2021112662 W CN2021112662 W CN 2021112662W WO 2022037509 A1 WO2022037509 A1 WO 2022037509A1
Authority
WO
WIPO (PCT)
Prior art keywords
bng
user equipment
network
gateway
network segment
Prior art date
Application number
PCT/CN2021/112662
Other languages
English (en)
French (fr)
Inventor
肖雅婷
吴歉歉
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to EP21857604.9A priority Critical patent/EP4199430A4/en
Publication of WO2022037509A1 publication Critical patent/WO2022037509A1/zh
Priority to US18/170,694 priority patent/US20230198796A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/2854Wide area networks, e.g. public data networks
    • H04L12/2856Access arrangements, e.g. Internet access
    • H04L12/2858Access network architectures
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/2854Wide area networks, e.g. public data networks
    • H04L12/2856Access arrangements, e.g. Internet access
    • H04L12/2869Operational details of access network equipments
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/2854Wide area networks, e.g. public data networks
    • H04L12/2856Access arrangements, e.g. Internet access
    • H04L12/2869Operational details of access network equipments
    • H04L12/287Remote access server, e.g. BRAS
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/66Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/22Alternate routing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/74Address processing for routing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/50Address allocation
    • H04L61/5007Internet protocol [IP] addresses
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/50Address allocation
    • H04L61/5007Internet protocol [IP] addresses
    • H04L61/503Internet protocol [IP] addresses using an authentication, authorisation and accounting [AAA] protocol, e.g. remote authentication dial-in user service [RADIUS] or Diameter

Definitions

  • the present application relates to the field of communications, and in particular, to an access control method and apparatus.
  • User equipment can access the network through a gateway such as a broadband network gateway (BNG).
  • BNG broadband network gateway
  • a user equipment can access the network through two gateways, one of which is the active gateway and the other is the standby gateway. When the active gateway is available, the user equipment uses the active gateway to access the network, and when the active gateway is unavailable, the user equipment uses the backup gateway to access the network.
  • the active gateways corresponding to each user equipment may not be exactly the same.
  • the first user's active gateway is the first gateway
  • the standby gateway is the second gateway
  • the second user's active gateway is the second gateway.
  • the standby gateway is the first gateway.
  • the network resources of one of the gateways may be unreasonably occupied.
  • the embodiment of the present application provides an access control method, which can avoid unreasonable occupation of network resources of a gateway.
  • an embodiment of the present application provides an access control method, which can be performed by a BNG CP.
  • the BNG CP can receive a first message from a first user equipment, and the first message is requesting the first user equipment to access the network, wherein the primary gateway of the first user equipment to access the network is the first BNG, and the backup gateway of the first user equipment to access the network is the second BNG.
  • the BNG CP can determine the IP address allocated for the first user equipment from the first network segment, and send the IP address of the first user equipment to the first user equipment.
  • the first network segment is only used to allocate an IP address to the user equipment that uses the first BNG as the active gateway and the second BNG as the backup gateway to access the network.
  • the first network segment is not used to assign an IP address to the user equipment that uses the first BNG as the backup gateway and the second BNG as the primary gateway to access the network.
  • the first BNG may form an active/standby relationship with multiple BNGs.
  • the first BNG and the second BNG may form an active/standby relationship; for another example, the first BNG and the third BNG may also form an active/standby relationship.
  • the second network segment can be used to assign an IP address to the user equipment, where the first BNG is used as the primary gateway.
  • the network segment and the second network segment are different.
  • the BNG CP of the first BNG may also be the IP address of the second user equipment.
  • the BNG CP of the first BNG may receive the second message from the second user equipment, and determine the IP address allocated for the second user equipment from the second network segment. After the BNG CP of the first BNG determines the IP address allocated for the second user equipment, the IP address of the second user equipment may be sent to the second user equipment.
  • the solutions of the embodiments of the present application can be applied to a network scenario in which CUs are separated, that is, the CP of the first BNG runs on a device independent of the first BNG.
  • the BNG CP that performs the access control method may be a virtual BNG CP module.
  • the solutions of the embodiments of the present application can be applied to a scenario where the CUs are not separated, that is, both the CP of the first BNG and the UP of the first BNG run on the CP of the first BNG.
  • the BNG CP performing the access control method may run on the first BNG CP.
  • the first BNG and the second BNG may correspond to the same vBNG CP module.
  • the vBNG CP may also assign an IP address to a third user equipment, where the third user equipment is a user equipment that uses the second BNG as the active gateway and the first BNG as the backup gateway to access the network.
  • the vBNG CP module may receive the third message from the third user equipment, and determine the IP address allocated for the third user equipment from the third network segment. After the vBNG CP module determines the IP address allocated to the third user equipment, it can send the IP address of the third user equipment to the third user equipment.
  • the BNG CP can obtain the corresponding relationship between the active gateway, the standby gateway and the network segment in advance. Assign an IP address to the user equipment in the segment.
  • the correspondence may include the correspondence between the first BNG, the second BNG and the first network segment, and when the first message is received, it may be determined from the first network segment as the first user equipment The assigned IP address.
  • the corresponding relationship may include the corresponding relationship between the first BNG, the third BNG and the second network segment, and when the second message is received, it may be determined from the second network segment as the second user equipment The assigned IP address.
  • the corresponding relationship may include the corresponding relationship between the second BNG, the first BNG and the third network segment, and when the third message is received, it may be determined from the third network segment as the third user equipment The assigned IP address.
  • the BNG CP is a virtual BNG CP module.
  • the virtual BNG CP module can The IP address is sent to the first user equipment via the first BNG.
  • the virtual BNG CP module can send the IP address of the first user equipment to the first BNG, and after receiving the IP address of the first user equipment, the first BNG can send the IP address of the first user equipment to the first user equipment .
  • the first BNG may also advertise the route corresponding to the first network segment as the primary route reaching the first user equipment to other network devices, so that other network devices can use this route to send data to the first user equipment.
  • the second BNG may advertise the route corresponding to the first network segment to other network devices as an alternate route to reach the first user equipment.
  • the BNG CP runs on the first BNG, and the BNG CP may also correspond to the first network
  • the route of the segment is advertised to other network devices as the primary route to the first user equipment, so that other network devices can use the route to send data to the first user equipment.
  • the route corresponding to the first network segment is the route to the first user equipment through the first BNG.
  • an embodiment of the present application provides an access control apparatus, which is applied to a broadband network gateway control plane BNG CP.
  • the apparatus includes: a receiving unit, configured to receive a first message from a first user equipment, where the The first message is used to request the first user equipment to access the network, the primary gateway of the first user equipment to access the network is the first BNG, and the backup gateway of the first user equipment to access the network is the second BNG; a determining unit, configured to determine, according to the first message, an Internet Protocol IP address allocated for the first user equipment from a first network segment, where the first network segment is used for the first BNG as the main
  • the gateway and the second BNG are used to assign IP addresses to user equipments that access the network by the standby gateway, and the first network segment is not used for using the first BNG as the standby gateway and the second BNG as the main function
  • the user equipment of the gateway allocates an IP address; the sending unit is configured to send the IP address of the first user equipment to the first user equipment.
  • the receiving unit is further configured to receive a second message from a second user equipment, where the second message is used to request the second user equipment to access a network, and the second user equipment
  • the primary gateway of the device access network is the first BNG
  • the standby gateway of the access network of the second user equipment is the third BNG
  • the determining unit is further configured to, according to the second message, select from the first BNG.
  • the IP address determined to be allocated to the second user equipment in the second network segment, where the second network segment is used for users who access the network with the first BNG as the primary gateway and the third BNG as the backup gateway The device allocates an IP address, and the first network segment is different from the second network segment; the sending unit is further configured to send the IP address of the second user equipment to the second user equipment.
  • the BNG CP is a virtual BNG CP module, or the BNG CP runs on the first BNG.
  • the receiving unit is further configured to receive a third message from a third user equipment, where the third message is used to request the first Three users access the network, the primary BNG of the third user equipment accessing the network is the second BNG, and the standby BNG of the third user equipment accessing the network is the first BNG;
  • the determining unit is further configured to determine, according to the third message, an IP address allocated to the third user equipment from a third network segment, where the third network segment is used to use the second BNG as an active gateway, and The first BNG is used as the backup gateway to assign IP addresses to the user equipment accessing the network, the first network segment, the second network segment and the third network segment are different from each other, and the second network segment is used for assigning an IP address to a user equipment that uses the first BNG as the active gateway and uses the third BNG as the backup gateway to access the network;
  • the sending unit is further configured to send the IP address of the third user equipment to the third user equipment
  • the apparatus further includes: an obtaining unit, configured to obtain a correspondence between the active gateway, the backup gateway and the network segment, where the correspondence includes one or more of the following: the first The correspondence between the BNG, the second BNG, and the first network segment; and, the correspondence between the first BNG, the third BNG, and the second network segment; and, the Correspondence between the second BNG, the first BNG, and the third network segment.
  • an obtaining unit configured to obtain a correspondence between the active gateway, the backup gateway and the network segment, where the correspondence includes one or more of the following: the first The correspondence between the BNG, the second BNG, and the first network segment; and, the correspondence between the first BNG, the third BNG, and the second network segment; and, the Correspondence between the second BNG, the first BNG, and the third network segment.
  • the sending unit is configured to: send the IP address of the first user equipment to the first user via the first BNG equipment.
  • the sending unit when the BNG CP runs on the first BNG, the sending unit is further configured to: use the route corresponding to the first network segment as the route to the first user equipment The active route is advertised to other network devices, and the route corresponding to the first network segment is a route to the first user equipment through the first BNG.
  • an embodiment of the present application provides a device.
  • the apparatus includes a processor and a memory.
  • the memory is used to store instructions or computer programs.
  • the processor is configured to execute the instructions or the computer program in the memory to execute the method described in any one of the above first aspects.
  • an embodiment of the present application provides a computer-readable storage medium, including an instruction or a computer program, which, when executed on a computer, causes the computer to execute the method described in any one of the above first aspects.
  • the embodiments of the present application provide a computer program product comprising an instruction or a computer program, which, when executed on a computer, causes the computer to execute the method described in any one of the above first aspects.
  • FIG. 1 is a schematic diagram of an exemplary application scenario provided by an embodiment of the present application
  • FIG. 2 is a schematic structural diagram of a BNG provided by an embodiment of the present application.
  • FIG. 3 is a schematic flowchart of an access control method provided by an embodiment of the present application.
  • FIG. 4 is a schematic diagram of an exemplary application scenario provided by an embodiment of the present application.
  • FIG. 5 is a schematic structural diagram of an access control apparatus provided by an embodiment of the present application.
  • FIG. 6 is a schematic structural diagram of a device provided by an embodiment of the present application.
  • the embodiment of the present application provides an access control method, which can avoid unreasonable occupation of network resources of a gateway.
  • FIG. 1 this figure is a schematic diagram of an exemplary application scenario provided by an embodiment of the present application.
  • the user equipment 101 can communicate with the BNG 103 through an access node (access node, AN) 102, and further, the user equipment 101 can access the network through the BNG 103.
  • the BNG functions similarly to a broadband remote access server (BRAS).
  • BRAS broadband remote access server
  • no other equipment may be included between the access node 102 and the BNG 103.
  • a sink node may be included between the access node 102 and the BNG 103.
  • the BNG 103 can authenticate the user equipment 101 and assign an Internet Protocol (IP) address to the user equipment 101.
  • IP Internet Protocol
  • the BNG shown in Figure 2 may include an access management (access management) module 201, a session management module 202, an authentication authorization accounting (authentication authorization accounting, AAA) management module 203, an address allocation module 204 and a service policy control module 205.
  • access management access management
  • session management session management
  • authentication authorization accounting authentication authorization accounting
  • address allocation address allocation
  • service policy control module 205 service policy control module
  • the access management module 201 and the session management module 202 are used to process the request message from the user equipment; the AAA management module 204 is used to authenticate the user equipment and obtain the service level agreement (Service Level Agreement, SLA) of the user equipment and other information.
  • the address allocation module 204 is used for allocating an IP address to the user equipment; the service policy control module 205 is used for determining the quality of service (quality of service, QoS) of the user equipment and so on.
  • the above-mentioned access management module 201, session management module 202, AAA management module 203, address allocation module 204 and service policy control module 205 belong to the control plane (CP) of the BNG.
  • the control plane may also be referred to as a control plane.
  • the BNG shown in FIG. 2 may further include a user plane (UP) 207, and the user plane may also be referred to as a forwarding plane or a forwarding plane.
  • the user plane includes functional modules for implementing data forwarding and functional modules interacting with the control plane, for example, including a routing control module, a forwarding control module, and the like.
  • the user equipment may send a request message to the BNG, where the request message is used to request the user equipment to access the network.
  • the forwarding plane of the BNG sends the request message to the access management module 201 of the control plane.
  • the access management module 201 and the session management module 202 of the control plane process the received request message and use the
  • the address allocation module 204 allocates an IP address to the user equipment.
  • the access management module 201 sends the IP address to the user plane, and the user plane sends the IP address to the user equipment.
  • control plane also needs to deliver the network segment route corresponding to the IP address to the user plane, and the user plane sends the network segment route to other forwarding devices in the network, such as the network device of the core network, so that the receiving The network device routed to the network segment can forward the data to the user equipment through the network segment route.
  • control plane of the BNG can be separated from the BNG, and the control plane of the BNG can be deployed on other devices, for example, on a control and management device or a server.
  • control plane and user plane of the BNG are separated, referred to as CU (control plane and user plane) separation.
  • CU control plane and user plane
  • the control plane that is separated from the BNG and deployed to other devices can also be called a virtual broadband network gateway control plane (vBNG CP) module.
  • vBNG CP virtual broadband network gateway control plane
  • one vBNG CP module can correspond to multiple BNGs.
  • one vBNG CP module can process request messages from multiple BNGs for requesting user equipment to access the network, and assign an IP address to the user equipment corresponding to the request message according to the request message.
  • vBNG CP module it is similar to the function of the control plane of the BNG, so you can refer to the description of the control plane of the BNG above, and the description will not be repeated here.
  • one user equipment may correspond to two gateways, one of which is the active gateway and the other is the standby gateway.
  • the active gateways corresponding to each user equipment may not be exactly the same.
  • the first BNG and the second BNG in a master-slave relationship the first user's active gateway is the first BNG
  • the standby gateway is the second BNG
  • the second user's active gateway is the second BNG.
  • the backup gateway is the first BNG.
  • the first BNG and the second BNG share a network segment, for example, network segment 1.
  • the control plane of the first BNG uses network segment 1 to assign IP addresses to the user equipment with the first BNG as the main gateway.
  • the control plane of the second BNG uses the network segment 1 to allocate an IP address to the user equipment whose main gateway is the second BNG.
  • the first BNG and the second BNG share the network segment 1
  • the network resources of the first BNG will be unreasonably occupied.
  • the second BNG first enables the user equipment to access the network
  • the network resources of the second BNG will be unreasonably occupied.
  • the first BNG first enables the user equipment to access the network as an example to illustrate:
  • the control plane of the first BNG will use network segment 1 to assign an IP address to user equipment A, and the corresponding Yes, the forwarding plane of the first BNG can advertise route 1 corresponding to network segment 1 as the primary route to user equipment A to other devices, where the forwarding path indicated by route 1 passes through the first BNG.
  • the forwarding plane of the second BNG may advertise route 2 corresponding to network segment 1 as a backup route to user equipment A to other devices, where the forwarding path indicated by route 2 passes through the second BNG.
  • the control plane of the second BNG will use network segment 1 to assign an IP address to user equipment B. In this case, both the active route and the standby route corresponding to network segment 1 have been advertised. Therefore, if other devices in the network send a packet to user equipment B, the packet will first be sent to the first BNG, and after the first BNG parses the packet, it is determined that the primary gateway of user equipment B is the second BNG. The BNG will forward the packet to the second BNG, and the second BNG will forward the packet to the user equipment B.
  • the packet sent by the network device to the user equipment B is forwarded to the second BNG of the primary gateway of the user equipment B through the first BNG of the backup gateway of the user equipment B, thus causing the network resources of the first BNG to be unreasonably occupied .
  • control plane of the first BNG may run on the first BNG, that is, the CU is not separated, and the control plane of the first BNG may also run on other devices, that is, the CU is separated.
  • control plane of the first BNG and the control plane of the second BNG may correspond to the same vBNG CP module.
  • the forwarding plane of the first BNG can receive the IP address of the user equipment from the vBNG CP module, for example, and use the route 1 corresponding to the network segment 1 as the main route to the user equipment A. Publish to other devices.
  • the forwarding plane of the second BNG may advertise route 2 corresponding to network segment 1 to other devices as a backup route to user equipment A.
  • an embodiment of the present application provides an access control method, which is described below with reference to the accompanying drawings.
  • the user equipment mentioned in the embodiments of the present application may include mobile terminals such as smart phones and tablet computers, and may also include terminal devices such as personal computers and smart TVs, which are not specifically limited in the embodiments of the present application.
  • FIG. 3 this figure is a schematic flowchart of an access control method provided by an embodiment of the present application.
  • the method shown in Figure 3 can be executed by the BNG CP.
  • the BNG CP can run on the BNG.
  • the BNG CP can be a vBNG CP module, which runs independently of the on other BNG devices.
  • the method may include the following steps, for example:
  • S101 Receive a first message from a first user equipment, where the first message is used to request the first user equipment to access the network, the primary gateway for the first user equipment to access the network is the first BNG, and the first user equipment accesses the network
  • the backup gateway of the network is the second BNG.
  • the first user equipment may send the first message to the BNG CP through a residential gateway (RG) and an access node.
  • RG residential gateway
  • the first user equipment may send the first message to the RG, the RG sends the first message to the AN, the AN sends the first message to the BNG, and the BNG sends the first message to the vBNG CP module.
  • the first user equipment can send the first message to the RG, the RG sends the first message to the AN, and the AN sends the first message to the UP of the BNG, and the UP of the BNG sends the first message to the AN.
  • a message is sent to the BNG CP.
  • the first message is used to request the first user equipment to access the network.
  • the first message may be an Ethernet point-to-point protocol (Point to Point Protocol over Ethernet, PPPoE) message, or may be an Ethernet Internet Protocol (Internet Protocol over Ethernet, IPoE) message, which is not specifically limited in the embodiments of this application.
  • PPPoE Point to Point Protocol over Ethernet
  • IPoE Internet Protocol over Ethernet
  • the gateway for the first user equipment to access the network includes a first BNG and a second BNG, where the first BNG is the primary gateway for the first user equipment to access the network, and the second BNG is the first user The backup gateway for the device to access the network.
  • the first user equipment may send the first message to the BNG CP of the first BNG and the BNG CP of the second BNG, and the BNG CP of the first BNG and the BNG CP of the second BNG determine that it is the first user equipment The active or standby gateway of the user equipment.
  • the BNG CP of the first BNG and the BNG CP of the second BNG may determine that they are the active gateway or the standby gateway of the first user equipment according to the network access control (media access control, MAC) address of the first user equipment gateway.
  • the BNG CP of the first BNG and the BNG CP of the second BNG may determine that they are the active gateway or the standby gateway of the first user equipment according to the user identity of the first user equipment.
  • S101-S103 are executed by the BNG CP of the active gateway of the first user equipment, that is, executed by the BNG CP of the first BNG. If the CU is separated, S101-S103 are performed by the vBNG CP module, which runs on a device independent of the first BNG. If the CU is not separated, S102 and S103 are performed by the BNG CP of the first BNG.
  • S102 Determine, according to the first message, the IP address allocated to the first user equipment from the first network segment, where the first network segment is used to access the network with the first BNG as the active gateway and the second BNG as the backup gateway The user equipment is assigned an IP address.
  • the BNG CP of the first BNG can allocate an IP address to the first user equipment.
  • the first BNG and the second BNG in order to prevent the first BNG and the second BNG from sharing a certain network segment, resulting in unreasonable occupation of the network resources of one of the BNGs mentioned above, in the embodiment of the present application, the first BNG and the second BNG The two BNGs no longer share the same network segment, but associate the network segment with the active gateway and the standby gateway.
  • the first BNG is the active gateway and the second BNG is the standby gateway, it corresponds to the first network segment.
  • the first network segment is only used for allocating an IP address to the user equipment with the first BNG as the active gateway and the second BNG as the standby gateway.
  • the first network segment no longer allocates an IP address to the user equipment with the first BNG as the standby gateway and the second BNG as the active gateway.
  • an IP address can be assigned to the user equipment using a network segment different from the first network segment, for example, using a third network segment
  • the network segment allocates IP addresses to the user equipment with the first BNG as the standby gateway and the second BNG as the active gateway.
  • the BNG CP of the first BNG may determine the first network segment according to the predetermined correspondence between the active gateway, the standby gateway and the network segment, and further determine the first network segment from the first The IP address assigned to the first user equipment is determined in the network segment.
  • the corresponding relationship includes at least the corresponding relationship between the first BNG, the second BNG and the first network segment.
  • S103 Send the IP address of the first user equipment to the first user equipment.
  • the IP address of the first user equipment may be sent to the first user equipment, so that the first user equipment can access the network by using the IP address.
  • the IP address of the first user equipment mentioned here is the IP address assigned to the first user equipment determined by the BNG CP of the first BNG in S102.
  • the virtual BNG CP module can send the IP address of the first user equipment to the first user equipment via the first BNG.
  • the virtual BNG CP module can send the IP address of the first user equipment to the first BNG, and after receiving the IP address of the first user equipment, the first BNG can send the IP address of the first user equipment to the first user equipment .
  • the first BNG may also advertise the route corresponding to the first network segment as the primary route reaching the first user equipment to other network devices, so that other network devices can use this route to send data to the first user equipment.
  • the second BNG may advertise the route corresponding to the first network segment to other network devices as a backup route to the first user equipment.
  • the first network segment can be used to allocate its IP address; for the user equipment with the first BNG as the standby gateway and the second BNG as the active gateway, the third network segment can be used to assign the IP address.
  • the second BNG enables the user equipment such as the third user equipment to access the network
  • the second The route advertised by the BNG is the route corresponding to the third network segment, and is no longer the route corresponding to the first network segment as in the conventional technology. Therefore, when the network device sends a packet to the third user equipment, the packet can be sent to the third user equipment through the second BNG, without first forwarding the packet to the first BNG, and then the first BNG It is forwarded to the second BNG, thereby avoiding unreasonable occupation of the network resources of the first BNG.
  • the first BNG and the second BNG may correspond to the same vBNG CP module.
  • the vBNG CP can also assign an IP address to the third user equipment, wherein the third user equipment is the second BNG as the main gateway and the first BNG as the backup gateway User equipment connected to the network.
  • the vBNG CP module may receive the third message from the third user equipment, and determine the IP address allocated for the third user equipment from the third network segment. After the vBNG CP module determines the IP address allocated to the third user equipment, it can send the IP address of the third user equipment to the third user equipment.
  • the principle is similar to the implementation principle of the vBNG CP module receiving the first message from the first user equipment, so the vBNG CP module receives the third message from the third user equipment.
  • the description of S101 above which will not be described in detail here.
  • the vBNG CP module After the vBNG CP module determines the IP address allocated for the third user equipment from the third network segment, it can send the IP address of the third user equipment to the third user equipment via the second BNG.
  • the virtual BNG CP module can send the IP address of the third user equipment to the second BNG, and after receiving the IP address of the third user equipment, the second BNG can send the IP address of the third user equipment to the third user equipment .
  • the second BNG may also advertise the route corresponding to the third network segment as the primary route to the third user equipment to other network devices, so that other network devices can use this route to send data to the third user equipment.
  • the first BNG may advertise the route corresponding to the third network segment to other network devices as a backup route to the third user equipment.
  • the first BNG may form an active/standby relationship with multiple BNGs.
  • the first BNG and the second BNG may form an active/standby relationship; for another example, the first BNG and the third BNG may also form an active/standby relationship.
  • the second network segment may be used to allocate it to the user equipment. IP addresses, wherein the first network segment, the second network segment and the third network segment are different from each other.
  • the BNG CP of the first BNG may also be the IP address of the second user equipment.
  • the BNG CP of the first BNG may receive the second message from the second user equipment, and determine the IP address allocated for the second user equipment from the second network segment. After the BNG CP of the first BNG determines the IP address allocated for the second user equipment, the IP address of the second user equipment may be sent to the second user equipment.
  • the principle is similar to the implementation principle of the BNG CP of the first BNG receiving the first message from the first user equipment, so the first
  • the specific implementation part of the BNG CP of the BNG receiving the second message from the second user equipment reference may be made to the description of S101 above, which will not be described in detail here.
  • the IP address of the second user equipment may be sent to the second user equipment via the first BNG.
  • the virtual BNG CP module can send the IP address of the second user equipment to the first BNG, and after receiving the IP address of the second user equipment, the first BNG can send the IP address of the second user equipment to the second user equipment .
  • the first BNG may also advertise the route corresponding to the second network segment as the primary route to the second user equipment to other network devices, so that other network devices can use this route to send data to the second user equipment.
  • the third BNG may advertise the route corresponding to the second network segment to other network devices as a backup route to the second user equipment.
  • FIG. 4 this figure is a schematic diagram of an exemplary application scenario provided by an embodiment of the present application.
  • the CU is separated, and the vBNG CP module 401 runs on the network management device.
  • the vBNG CP module 401 corresponds to multiple BNGs.
  • the vBNG CP module 401 corresponds to BNG 402 , BNG 403 and BNG 404 .
  • BNG 402 and BNG 403 have a master-standby relationship with each other, and BNG 402 and BNG 404 have a master-standby relationship with each other.
  • the corresponding relationship shown in Table 1 below is pre-stored in the vBNG CP module 401.
  • network segment 1 is used to assign IP addresses to user equipment with BNG 402 as the main gateway and BNG 403 as the backup gateway to access the network;
  • network segment 2 is used for BNG 402 as the main gateway The gateway and BNG 404 allocate IP addresses to the user equipment connected to the network by the backup gateway;
  • network segment 3 is used to allocate IP addresses to the user equipment connected to the network with the BNG 403 as the main gateway and the BNG 404 as the backup gateway.
  • the vBNG CP module 401 may execute the access control method provided by the above embodiments of the present application, and allocate an IP address to the user equipment that accesses the network through the BNG 402 or the BNG 403.
  • the BNG 402 can correspond to the first BNG in the above embodiments
  • the BNG 403 can correspond to the second BNG in the above embodiments
  • the BNG 404 can correspond to The third BNG in the above embodiment.
  • Network segment 1 may correspond to the first network segment in the above embodiment
  • network segment 2 may correspond to the second network segment in the above embodiment
  • network segment 3 may correspond to the third network segment in the above embodiment.
  • the embodiments of the present application further provide a corresponding apparatus, which is described below with reference to the accompanying drawings.
  • FIG. 5 this figure is a schematic structural diagram of an access control apparatus provided by an embodiment of the present application.
  • the access control apparatus 500 shown in FIG. 5 can be applied to a BNG CP, for example, to execute the access control method performed by the BNG CP in the above method embodiments.
  • the access control apparatus 500 includes: a receiving unit 501 , a determining unit 502 and a sending unit 503 .
  • a receiving unit 501 configured to receive a first message from a first user equipment, where the first message is used to request the first user equipment to access a network, and the primary gateway for the first user equipment to access the network is The first BNG, the backup gateway of the first user equipment accessing the network is the second BNG.
  • a determining unit 502 configured to determine, according to the first message, an Internet Protocol IP address allocated to the first user equipment from a first network segment, where the first network segment is used for the first BNG as the main function
  • the gateway and the second BNG assign IP addresses to the user equipment that the backup gateway accesses the network, and the first network segment is not used for using the first BNG as the backup gateway and the second BNG as the primary gateway
  • the user equipment is assigned an IP address.
  • the sending unit 503 is configured to send the IP address of the first user equipment to the first user equipment.
  • the receiving unit 501 is further configured to receive a second message from a second user equipment, where the second message is used to request the second user equipment to access the network, the second message
  • the primary gateway of the access network of the user equipment is the first BNG
  • the standby gateway of the access network of the second user equipment is the third BNG.
  • the determining unit 502 is further configured to determine, according to the second message, an IP address assigned to the second user equipment from a second network segment, where the second network segment is configured to use the first BNG Allocate an IP address to the user equipment of the primary gateway and the third BNG accessing the network for the backup gateway, where the first network segment is different from the second network segment.
  • the sending unit 503 is further configured to send the IP address of the second user equipment to the second user equipment.
  • the BNG CP is a virtual BNG CP module, or the BNG CP runs on the first BNG.
  • the BNG CP is a virtual BNG CP module
  • the receiving unit 501 is further configured to receive a third message from a third user equipment, where the third message is used to request the third user to access the network, and the third user equipment to access the primary user of the network.
  • the BNG is the second BNG, and the backup BNG that the third user equipment accesses the network is the first BNG.
  • the determining unit 502 is further configured to determine, according to the third message, an IP address assigned to the third user equipment from a third network segment, where the third network segment is configured to use the second BNG Allocate an IP address to the user equipment that is the active gateway and uses the first BNG as the standby gateway to access the network, the first network segment, the second network segment, and the third network segment are different, and the first network segment is different.
  • the second network segment is used for allocating an IP address to the user equipment accessing the network with the first BNG as the active gateway and the third BNG as the backup gateway.
  • the sending unit 503 is further configured to send the IP address of the third user equipment to the third user equipment.
  • the apparatus further includes: an obtaining unit.
  • the obtaining unit is used to obtain the corresponding relationship between the active gateway, the backup gateway and the network segment, and the corresponding relationship includes one or more of the following:
  • the sending unit 503 is used to:
  • the sending unit 503 when the BNG CP runs on the first BNG, the sending unit 503 is further configured to:
  • the apparatus 500 is an apparatus corresponding to the routing processing method provided by the above method embodiments, the specific implementation of each unit of the apparatus 500 is the same concept as the above method embodiments.
  • the specific implementation of the unit reference may be made to the description part of the access control method in the above method embodiments, which will not be repeated here.
  • the aforementioned access control apparatus 500 may have a hardware structure as shown in FIG. 6 , which is a schematic structural diagram of a device provided by an embodiment of the present application.
  • the device 600 includes: a processor 610 , a communication interface 620 and a memory 630 .
  • the number of processors 610 in the device 600 may be one or more, and one processor is taken as an example in FIG. 6 .
  • the processor 610, the communication interface 620, and the memory 630 may be connected through a bus system or other manners, wherein the connection through the bus system 640 is taken as an example in FIG. 6 .
  • the processor 610 may be a central processing unit (CPU), a network processor (NP), or a combination of CPU and NP.
  • the processor 610 may further include hardware chips.
  • the above-mentioned hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or a combination thereof.
  • the above-mentioned PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof.
  • the memory 630 may include a volatile memory (English: volatile memory), such as random-access memory (RAM); the memory 630 may also include a non-volatile memory (English: non-volatile memory), such as a fast memory A flash memory (English: flash memory), a hard disk drive (HDD) or a solid-state drive (SSD); the memory 630 may also include a combination of the above-mentioned types of memory.
  • the memory 630 may, for example, store the aforementioned correspondence between the active gateway, the standby gateway and the network segment.
  • the memory 630 stores an operating system and programs, executable modules or data structures, or their subsets, or their extended sets, wherein the programs may include various operation instructions for implementing various operations.
  • the operating system may include various system programs for implementing various basic services and handling hardware-based tasks.
  • the processor 610 may read the program in the memory 630 to implement the access control method provided by the embodiment of the present application.
  • the bus system 640 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus or the like.
  • PCI peripheral component interconnect
  • EISA extended industry standard architecture
  • the bus system 640 can be divided into an address bus, a data bus, a control bus, and the like. For ease of presentation, only one thick line is used in FIG. 6, but it does not mean that there is only one bus or one type of bus.
  • Embodiments of the present application further provide a computer-readable storage medium, including instructions or computer programs, which, when executed on a computer, cause the computer to execute the access control method provided by the above embodiments.
  • the disclosed system, apparatus and method may be implemented in other manners.
  • the apparatus embodiments described above are only illustrative.
  • the division of units is only a logical business division. In actual implementation, there may be other division methods.
  • multiple units or components may be combined or integrated. to another system, or some features can be ignored, or not implemented.
  • the shown or discussed mutual coupling or direct coupling or communication connection may be through some interfaces, indirect coupling or communication connection of devices or units, and may be in electrical, mechanical or other forms.
  • Units described as separate components may or may not be physically separated, and components shown as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution in this embodiment.
  • each service unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit.
  • the above-mentioned integrated unit may be implemented in the form of hardware, or may be implemented in the form of a software business unit.
  • the integrated unit if implemented as a software business unit and sold or used as a stand-alone product, may be stored in a computer-readable storage medium.
  • the technical solutions of the present application can be embodied in the form of software products in essence, or the parts that contribute to the prior art, or all or part of the technical solutions, and the computer software products are stored in a storage medium , including several instructions to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present application.
  • the aforementioned storage medium includes: U disk, mobile hard disk, Read-Only Memory (ROM, Read-Only Memory), Random Access Memory (RAM, Random Access Memory), magnetic disk or optical disk and other media that can store program codes .
  • the services described in the present invention may be implemented by hardware, software, firmware or any combination thereof.
  • the services may be stored on or transmitted over as one or more instructions or code on a computer-readable medium.
  • Computer-readable media includes both computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another.
  • a storage medium can be any available medium that can be accessed by a general purpose or special purpose computer.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请实施例公开了一种接入控制方法,BNG CP可以接收来自于第一用户设备的第一消息,该第一消息用于请求第一用户设备接入网络,第一用户设备接入网络的主用网关为第一BNG,第一用户设备接入网络的备用网关为第二BNG。BNG CP接收到第一消息后,可以从第一网段中确定为第一用户设备分配的IP地址,并将第一用户设备的IP地址发送给第一用户设备。其中,第一网段仅用于为以第一BNG为主用网关、且以第二BNG为备用网关接入网络的用户设备分配IP地址,也就是说,该第一网段不用于以第一BNG为备用网关、且以第二BNG为主用网关接入网络的用户设备分配IP地址。由此可见,利用本方案,即使第一BNG首先使得用户设备接入网络,第一BNG的网络资源也不会被不合理占用。

Description

一种接入控制方法及装置
本申请要求于2020年8月19日提交的申请号为202010837047.9、申请名称为“一种接入控制方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及通信领域,尤其涉及一种接入控制方法及装置。
背景技术
用户设备可以通过网关例如宽带网络网关(broadband network gateway,BNG)接入网络。在一些场景中,一个用户设备可以通过两个网关接入网络,其中一个为主用网关,另外一个为备用网关。当主用网关可用时,用户设备利用主用网关接入网络,当主用网关不可用时,用户设备利用备用网关接入网络。
当多个用户设备均对应相同的两个互为主备关系的网关时,各个用户设备对应的主用网关可以不完全相同。例如,对于互为主备关系的第一网关和第二网关而言,第一用户的主用网关为第一网关,备用网关为第二网关,第二用户的主用网关为第二网关,备用网关为第一网关。对于这种情况,其中一个网关的网络资源可能会被不合理占用。
发明内容
本申请实施例提供了一种接入控制方法,可以避免网关的网络资源被不合理占用。
第一方面,本申请实施例提供了一种接入控制方法,该方法可以由BNG CP执行,在一个示例中,BNG CP可以接收来自于第一用户设备的第一消息,该第一消息用于请求第一用户设备接入网络,其中,第一用户设备接入网络的主用网关为第一BNG,第一用户设备接入网络的备用网关为第二BNG。BNG CP接收到第一消息中,可以从第一网段中确定为第一用户设备分配的IP地址,并将第一用户设备的IP地址发送给第一用户设备。在本申请实施例中,第一网段仅用于为以第一BNG为主用网关、且以第二BNG为备用网关接入网络的用户设备分配IP地址。换言之,该第一网段不用于以第一BNG为备用网关、且以第二BNG为主用网关接入网络的用户设备分配IP地址。由此可见,利用本申请实施例的方案,即使第一BNG首先使得用户设备接入网络,第一BNG的网络资源也不会被不合理占用。
在一种实现方式中,第一BNG可以和多个BNG均构成主备关系。例如,第一BNG和第二BNG可以构成主备关系;又如,第一BNG和第三BNG也可以构成主备关系。为了避免BNG的网络资源被不合理占用,对于以第一BNG为主用网关、以第三BNG为备用网关的用户设备而言,可以利用第二网段为其分配IP地址,其中,第一网段和第二网段不同。对于这种情况,第一BNG的BNG CP还可以为第二用户设备IP地址。在一个示例中,第一BNG的BNG CP可以接收来自于第二用户设备的第二消息,并从第二网段中确定为第二用户设备分配的IP地址。第一BNG的BNG CP确定为第二用户设备分配的IP地址之后,可以将第二用户设备的IP地址发送给第二用户设备。
在一种实现方式中,本申请实施例的方案,可以应用于CU分离的网络场景中,即第一BNG的CP运行在独立于第一BNG的设备上。对于这种情况,执行接入控制方法的BNG CP,可以是虚拟BNG CP模块。
在一种实现方式中,本申请实施例的方案,可以应用于CU不分离的场景,即第一BNG的CP和第一BNG的UP均运行在第一BNG CP上。对于这种情况,执行接入控制方法的BNG CP,可以运行在第一BNG CP上。
在一种实现方式中,若本申请实施例的方案应用于CU分离的网络场景中,则第一BNG和第二BNG可以对应同一vBNG CP模块。对于这种情况,该vBNG CP还可以为第三用户设备分配IP地址,其中,第三用户设备为以第二BNG为主用网关、且以第一BNG为备用网关接入网络的用户设备。在一个示例中,vBNG CP模块可以接收来自于第三用户设备的第三消息,并从第三网段中确定为第三用户设备分配的IP地址。vBNG CP模块确定为第三用户设备分配的IP地址之后,可以将第三用户设备的IP地址发送给第三用户设备。
在一种实现方式中,BNG CP可以预先获取主用网关、备用网关和网段之间的对应关系,当接收到请求用户设备接入网络的消息时,可以根据该对应关系,从对应的网段中为用户设备分配IP地址。该对应关系可以包括所述第一BNG、所述第二BNG和所述第一网段之间的对应关系,当接收到第一消息时,可以从第一网段中确定为第一用户设备分配的IP地址。该对应关系可以包括所述第一BNG、所述第三BNG和所述第二网段之间的对应关系,当接收到第二消息时,可以从第二网段中确定为第二用户设备分配的IP地址。该对应关系可以包括所述第二BNG、所述第一BNG和所述第三网段之间的对应关系,当接收到第三消息时,可以从第三网段中确定为第三用户设备分配的IP地址。
在一种实现方式中,当本申请实施例的方案应用于CU分离的网络场景中时,所述BNG CP为虚拟BNG CP模块,对于这种情况,虚拟BNG CP模块可以将第一用户设备的IP地址经由第一BNG发送给第一用户设备。换言之,虚拟BNG CP模块可以将第一用户设备的IP地址发送给第一BNG,第一BNG接收到第一用户设备的IP地址之后,可以将第一用户设备的IP地址发送给第一用户设备。另外,第一BNG还可以将对应第一网段路由作为达到第一用户设备的主用路由发布给其它网络设备,以便于其它网络设备利用该路由向第一用户设备发送数据。另外,第二BNG可以将对应的第一网段的路由作为到达第一用户设备的备用路由发布给其它网络设备。
在一种实现方式中,当本申请实施例的方案应用于CU未分离的网络场景中时,所述BNG CP运行在第一BNG上,则所述BNG CP还可以将对应所述第一网段的路由作为到达所述第一用户设备的主用路由向其它网络设备发布,以便于其它网络设备利用该路由向第一用户设备发送数据。其中:对应所述第一网段的路由为经过所述第一BNG到达所述第一用户设备的路由。
第二方面,本申请实施例提供了一种接入控制装置,应用于宽带网络网关控制平面BNG CP,所述装置包括:接收单元,用于接收来自于第一用户设备的第一消息,所述第一消息用于请求所述第一用户设备接入网络,所述第一用户设备接入网络的主用网关为第一BNG,所述第一用户设备接入网络的备用网关为第二BNG;确定单元,用于根据所述第一 消息,从第一网段中确定为所述第一用户设备分配的互联网协议IP地址,所述第一网段用于为以第一BNG为主用网关、第二BNG为备用网关接入网络的用户设备分配IP地址,并且,所述第一网段不用于为以所述第一BNG为备用网关、且以所述第二BNG为主用网关的用户设备分配IP地址;发送单元,用于将所述第一用户设备的IP地址发送给所述第一用户设备。
在一种实现方式中,所述接收单元,还用于接收来自于第二用户设备的第二消息,所述第二消息用于请求所述第二用户设备接入网络,所述第二用户设备接入网络的主用网关为所述第一BNG,所述第二用户设备的接入网络的备用网关为第三BNG;所述确定单元,还用于根据所述第二消息,从第二网段中确定为所述第二用户设备分配的IP地址,所述第二网段用于为以所述第一BNG为主用网关、所述第三BNG为备用网关接入网络的用户设备分配IP地址,所述第一网段与所述第二网段不同;所述发送单元,还用于将所述第二用户设备的IP地址发送给所述第二用户设备。
在一种实现方式中,所述BNG CP为虚拟BNG CP模块,或者,所述BNG CP运行在所述第一BNG上。
在一种实现方式中,当所述BNG CP为虚拟BNG CP模块时,所述接收单元,还用于接收来自于第三用户设备的第三消息,所述第三消息用于请求所述第三用户接入网络,所述第三用户设备接入网络的主用BNG为所述第二BNG,所述第三用户设备接入网络的备用BNG为所述第一BNG;所述确定单元,还用于根据所述第三消息,从第三网段中确定为所述第三用户设备分配的IP地址,所述第三网段用于为以所述第二BNG为主用网关、且以所述第一BNG为备用网关接入网络的用户设备分配IP地址,所述第一网段、第二网段和所述第三网段各不相同,所述第二网段用于为以所述第一BNG为主用网关、且以所述第三BNG为备用网关接入网络的用户设备分配IP地址;所述发送单元,还用于将所述第三用户设备的IP地址发送给所述第三用户设备。
在一种实现方式中,所述装置还包括:获取单元,用于获取主用网关、备用网关和网段之间的对应关系,所述对应关系包括以下一项或者多项:所述第一BNG、所述第二BNG和所述第一网段之间的对应关系;以及,所述第一BNG、所述第三BNG和所述第二网段之间的对应关系;以及,所述第二BNG、所述第一BNG和所述第三网段之间的对应关系。
在一种实现方式中,当所述BNG CP为虚拟BNG CP模块时,所述发送单元,用于:将所述第一用户设备的IP地址经由所述第一BNG发送给所述第一用户设备。
在一种实现方式中,当所述BNG CP运行在所述第一BNG上时,所述发送单元,还用于:将对应所述第一网段的路由作为到达所述第一用户设备的主用路由向其它网络设备发布,所述对应所述第一网段的路由为经过所述第一BNG到达所述第一用户设备的路由。
第三方面,本申请实施例提供了一种设备。所述设备包括处理器和存储器。所述存储器用于存储指令或计算机程序。所述处理器用于执行所述存储器中的所述指令或计算机程序,执行以上第一方面任意一项所述的方法。
第四方面,本申请实施例提供了一种计算机可读存储介质,包括指令或计算机程序,当其在计算机上运行时,使得计算机执行以上第一方面任意一项所述的方法。
第五方面,本申请实施例提供了一种包含指令或计算机程序的计算机程序产品,当其在计算机上运行时,使得计算机执行以上第一方面任意一项所述的方法。
附图说明
为了更清楚地说明本申请实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本申请中记载的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为本申请实施例提供的一种示例性应用场景示意图;
图2为本申请实施例提供的一个BNG的结构示意图;
图3为本申请实施例提供的一种接入控制方法的流程示意图;
图4为本申请实施例提供的一个示例性应用场景示意图;
图5为本申请实施例提供的一种接入控制装置的结构示意图;
图6为本申请实施例提供的一种设备的结构示意图。
具体实施方式
本申请实施例提供了一种接入控制方法,可以避免网关的网络资源被不合理占用。
为方便理解,首先对本申请实施例可能的应用场景进行介绍。
参见图1,该图为本申请实施例提供的一种示例性应用场景示意图。
在图1所示的场景中,用户设备101可以通过接入节点(access node,AN)102与BNG 103进行通信,进一步地,用户设备101可以通过该BNG 103接入网络。在一些实施例中,BNG的功能与宽带远程接入服务器(broadband remote access server,BRAS)类似。在一些实施例中,接入节点102和BNG 103之间可以不包括其它设备。在一些实施例中,接入节点102和BNG 103之间可以包括汇聚节点。
用户设备101通过BNG 103接入网络时,BNG 103可以为对用户设备101进行身份认证,并为用户设备101分配互联网协议(Internet Protocol,IP)地址。可参见图2进行理解,图2为本申请实施例提供的一个BNG的结构示意图。
图2所示的BNG,可以包括接入管理(access management)模块201、会话管理模块202、认证授权记账(authentication authorization accounting,AAA)管理模块203、地址分配模块204和业务策略控制模块205。其中:
接入管理模块201和会话管理模块202用于对来自于用户设备的请求消息进行处理;AAA管理模块204用于对用户设备进行认证,并获得用户设备的服务级别协议(Service Level Agreement,SLA)等信息。地址分配模块204用于为用户设备分配IP地址;业务策略控制模块205用于确定用户设备的服务质量(quality of service,QoS)等。
上述接入管理模块201、会话管理模块202、AAA管理模块203、地址分配模块204和业务策略控制模块205,属于所述BNG的控制平面(control plane,CP)。其中,控制平面也可以被称为控制面。
图2所示的BNG,还可以包括用户平面(user plane,UP)207,用户平面也可被称为转发平面或者转发面。所述用户平面包括用于实现数据转发的功能模块以及与控制面交互的功能模块,例如包括路由控制模块、转发控制模块等等。
在一个示例中,用户设备可以向BNG发送请求消息,该请求消息用于请求用户设备接入网络。BNG的转发面接收到该请求消息之后,将该请求消息发送给控制面的接入管理模块201,控制面的接入管理模块201和会话管理模块202对接收到的请求消息进行处理,并利用AAA管理模块203对用户设备进行身份认证后,由地址分配模块204为用户设备分配IP地址。地址分配模块204为用户设备分配IP地址之后,通过接入管理模块201将该IP地址发送给用户平面,由用户平面将该IP地址发送给用户设备。
另外,控制平面还需要将该IP地址对应的网段路由下发给用户平面,由用户平面将该网段路由发送给网络中的其它转发设备,例如转发给核心网的网络设备,以使得接收到该网段路由的网络设备可以通过该网段路由将数据转发给用户设备。
随着网络技术的发展,可以将BNG的控制面从BNG中分离出来,将BNG的控制面部署至其它设备上,例如部署至控制管理设备或者服务器上。换言之,将BNG的控制面和用户平面进行了分离,简称CU(control plane and user plane)分离。对于CU分离的场景,从BNG中分离出去、并部署至其它设备上的控制面,也可以被称为虚拟宽带网络网关控制平面(virtual broadband network gateway control plane,vBNG CP)模块。在CU分离的场景中,一个vBNG CP模块可以对应多个BNG。换言之,一个vBNG CP模块可以处理来自多个BNG的用于请求用户设备接入网络的请求消息,并根据该请求消息为该请求消息对应的用户设备分配IP地址。
关于vBNG CP模块的功能,其与BNG的控制平面的功能类似,故可以参考上文对BNG的控制平面的描述部分,此处不再重复描述。
关于vBNG CP模块与BNG之间的交互,实际上是vBNG CP模块与BNG的UP之间的交互,具体可以可以参考上文BNG的控制平面和用户平面的交互的描述部分,此处不再重复说明。
在一些网络场景中,一个用户设备可以对应两个网关,其中一个网关为主用网关,另一个为备用网关。当多个用户设备均对应相同的两个互为主备关系的网关时,各个用户设备对应的主用网关可以不完全相同。例如,对于互为主备关系的第一BNG和第二BNG而言,第一用户的主用网关为第一BNG,备用网关为第二BNG,第二用户的主用网关为第二BNG,备用网关为第一BNG。对于这种情况,第一BNG和第二BNG共享一个网段,例如共享网段1,第一BNG的控制平面利用网段1为以第一BNG为主用网关的用户设备分配IP地址,第二BNG的控制平面利用网段1为以第二BNG为主用网关的用户设备分配IP地址。
对于第一BNG和第二BNG共享网段1的这种情况,若第一BNG首先使得用户设备接入网络,则第一BNG的网络资源会被不合理占用。若第二BNG首先使得用户设备接入网络,则第二BNG的网络资源会被不合理占用。接下来以第一BNG首先使得用户设备接入网络为例进行说明:
对于以第一BNG为主用路由的用户设备A而言,第一BNG接收到用户设备A的接入请求之后,第一BNG的控制平面会利用网段1为用户设备A分配IP地址,相应的,第一BNG的转发平面可以将网段1对应的路由1作为到达用户设备A的主用路由发布给其它设备,其中,路由1指示的转发路径经过第一BNG。第二BNG的转发平面可以将网段1对应的路由2作为到达用户设备A的备用路由发布给其它设备,其中,路由2指示的转发路径经过第二BNG。
用户设备A通过第一BNG接入网络之后,若以第二BNG为主用路由的用户设备B请求接入网络,则第二BNG的控制平面会利用网段1为用户设备B分配IP地址。对于这种情况,由于网段1对应的主用路由和备用路由都已经发布。因此,若网络中的其它设备向用户设备B发送报文,则该报文会首先发送给第一BNG,第一BNG对该报文进行解析之后,确定用户设备B的主用网关为第二BNG,则会将该报文转发给第二BNG,由第二BNG将该报文转发给用户设备B。由此可见,网络设备发送给用户设备B的报文经过了用户设备B的备用网关第一BNG转发给用户设备B的主用网关第二BNG,从而导致第一BNG的网络资源被不合理占用。
在以上的示例中,第一BNG的控制平面可以运行在第一BNG上,即CU未分离,第一BNG的控制平面也可以运行在其它设备上,即CU分离。在CU分离的场景中,第一BNG的控制平面的第二BNG的控制平面可以对应同一个vBNG CP模块。
需要说明的是,在CU分离的场景中,第一BNG的转发平面例如可以从vBNG CP模块处接收用户设备的IP地址,并将网段1对应的路由1作为到达用户设备A的主用路由发布给其它设备。相应的,第二BNG的转发平面可以将网段1对应的路由2作为到达用户设备A的备用路由发布给其它设备。
为了解决上述第一BNG的网络资源被不合理占用的问题,本申请实施例提供了一种接入控制方法,以下结合附图介绍该方法。
本申请实施例中提及的用户设备,可以包括智能手机、平板电脑等移动终端,也可以包括个人计算机、智能电视机等终端设备,本申请实施例不做具体限定。
参见图3,该图为本申请实施例提供的一种接入控制方法的流程示意图。
图3所示的方法,可以由BNG CP执行,在CU不分离的场景中,该BNG CP可以运行在BNG上,在CU分离的场景中,该BNG CP可以为vBNG CP模块,运行在独立于BNG的其它设备上。该方法例如可以包括如下步骤:
S101:接收来自于第一用户设备的第一消息,第一消息用于请求第一用户设备接入网络,第一用户设备接入网络的主用网关为第一BNG,第一用户设备接入网络的备用网关为第二BNG。
在一些实施例中,第一用户设备可以通过家庭网关(residential gateway,RG)和接入节点将第一消息发送给BNG CP。在CU分离的场景中,第一用户设备可以将第一消息发送给RG,由RG将第一消息发送给AN,再由AN将第一消息发送给BNG,由BNG将第一消息发送给vBNG CP模块。在CU不分离的场景中,第一用户设备可以将第一消息发送给RG,由RG将第一消息发送给AN,再由AN将第一消息发送给BNG的UP,由BNG 的UP将第一消息发送给BNG CP。
在本申请实施例中,第一消息用于请求第一用户设备接入网络。第一消息可以是以太网点到点协议(Point to Point Protocol over Ethernet,PPPoE)报文,也可以是以太网互联网协议(Internet Protocol over Ethernet,IPoE)报文,本申请实施例不做具体限定。
在本申请实施例中,第一用户设备接入网络的网关包括第一BNG和第二BNG,其中,第一BNG为第一用户设备接入网络的主用网关,第二BNG为第一用户设备接入网络的备用网关。在一些实施例中,第一用户设备可以将第一消息发送给第一BNG的BNG CP和第二BNG的BNG CP,由第一BNG的BNG CP和第二BNG的BNG CP确定自身是第一用户设备的主用网关或备用网关。作为一个示例,第一BNG的BNG CP和第二BNG的BNG CP可以根据第一用户设备的网络接入控制(media access control,MAC)地址,确定自身是第一用户设备的主用网关或备用网关。作为又一个示例,第一BNG的BNG CP和第二BNG的BNG CP可以根据第一用户设备的用户标识,确定自身为是第一用户设备的主用网关或备用网关。
在本申请实施例中,S101-S103由第一用户设备的主用网关的BNG CP执行,即由第一BNG的BNG CP执行。若CU分离,则S101-S103由vBNG CP模块执行,该vBNG CP模块运行在独立于第一BNG的设备上。若CU不分离,则S102和S103由第一BNG的BNG CP执行。
S102:根据第一消息,从第一网段中确定为第一用户设备分配的IP地址,第一网段用于为以第一BNG为主用网关、第二BNG为备用网关接入网络的用户设备分配IP地址。
第一BNG的BNG CP接收到第一消息之后,可以为第一用户设备分配IP地址。在本申请实施例中,为了避免第一BNG和第二BNG共享某一网段,导致前文提及的其中一个BNG的网络资源被不合理占用,在本申请实施例中,第一BNG和第二BNG不再共享同一网段,而是将网段与主用网关和备用网关进行关联,第一BNG为主用网关、第二BNG为备用网关时,其对应第一网段。该第一网段仅用于为以第一BNG为主用网关、第二BNG为备用网关的用户设备分配IP地址。换言之,第一网段不再为以第一BNG为备用网关、第二BNG为主用网关的用户设备分配IP地址。在一个示例中,对于以第一BNG为备用网关、第二BNG为主用网关的用户设备而言,可以利用不同于第一网段的其它网段为其分配IP地址,例如,利用第三网段为以第一BNG为备用网关、第二BNG为主用网关的用户设备分配IP地址。
在本申请实施例的一种实现方式中,第一BNG的BNG CP可以根据预先确定的主用网关、备用网关和网段之间的对应关系,确定第一网段,并进一步地从第一网段中确定为第一用户设备分配的IP地址。其中,该对应关系至少包括第一BNG、第二BNG和第一网段之间的对应关系。
S103:将第一用户设备的IP地址发送给第一用户设备。
第一BNG的BNG CP确定为第一用户设备分配的IP地址之后,可以将第一用户设备的IP地址发送给第一用户设备,以便于第一用户设备利用该IP地址接入网络。此处提及的第一用户设备的IP地址,即为S102中第一BNG的BNG CP所确定的为第一用户设备分 配的IP地址。
在本申请实施例中,若所述BNG CP为虚拟BNG CP模块,即在CU分离的场景中,虚拟BNG CP模块可以将第一用户设备的IP地址经由第一BNG发送给第一用户设备。换言之,虚拟BNG CP模块可以将第一用户设备的IP地址发送给第一BNG,第一BNG接收到第一用户设备的IP地址之后,可以将第一用户设备的IP地址发送给第一用户设备。
另外,第一BNG还可以将对应第一网段路由作为达到第一用户设备的主用路由发布给其它网络设备,以便于其它网络设备利用该路由向第一用户设备发送数据。相应的,第二BNG可以将对应第一网段的路由作为到达第一用户设备的备用路由发布给其它网络设备。
通过以上描述可知,由于第一BNG和第二BNG不再共享同一网段,对于以第一BNG为主用网关、第二BNG为备用网关的用户设备而言,可以利用第一网段其分配IP地址;对于以第一BNG为备用网关、第二BNG为主用网关的用户设备而言,可以利用第三网段其分配IP地址。即使第一BNG首先使得第一用户设备接入网络,则由于第一BNG发布的路由为对应第一网段的路由,而第二BNG使得用户设备例如第三用户设备接入网络时,第二BNG发布的路由为对应第三网段的路由,而不再如传统技术中那样,也是对应第一网段的路由。因此,当网络设备向第三用户设备发送报文时,可以通过第二BNG将该报文发送给第三用户设备,而不会先将该报文转发给第一BNG,再由第一BNG转发给第二BNG,从而避免第一BNG的网络资源被不合理占用。
在本申请实施例中,若CU分离,则第一BNG和第二BNG可以对应同一vBNG CP模块。若前述S101-S103由vBNG CP模块执行,则该vBNG CP还可以为第三用户设备分配IP地址,其中,第三用户设备为以第二BNG为主用网关、且以第一BNG为备用网关接入网络的用户设备。在一个示例中,vBNG CP模块可以接收来自于第三用户设备的第三消息,并从第三网段中确定为第三用户设备分配的IP地址。vBNG CP模块确定为第三用户设备分配的IP地址之后,可以将第三用户设备的IP地址发送给第三用户设备。
关于vBNG CP模块接收来自于第三用户设备的第三消息的具体实现,其原理与vBNG CP模块接收来自于第一用户设备的第一消息的实现原理类似,故而vBNG CP模块接收来自于第三用户设备的第三消息的具体实现部分,可以参考上文对于S101的描述部分,此处不再详述。
关于第三网段,可以参考上文S102中对于第三网段的描述部分,此处不再重复描述。
vBNG CP模块从第三网段中确定为第三用户设备分配的IP地址之后,可以经由第二BNG将第三用户设备的IP地址发送给第三用户设备。换言之,虚拟BNG CP模块可以将第三用户设备的IP地址发送给第二BNG,第二BNG接收到第三用户设备的IP地址之后,可以将第三用户设备的IP地址发送给第三用户设备。
另外,第二BNG还可以将对应第三网段路由作为达到第三用户设备的主用路由发布给其它网络设备,以便于其它网络设备利用该路由向第三用户设备发送数据。另外,第一BNG可以将对应第三网段的路由作为到达第三用户设备的备用路由发布给其它网络设备。
在一些实施例中,对于第一BNG而言,其可以和多个BNG均构成主备关系。例如, 如上文所述,第一BNG和第二BNG可以构成主备关系;又如,第一BNG和第三BNG也可以构成主备关系。为了避免BNG的网络资源被不合理占用,在本申请实施例中,对于以第一BNG为主用网关、以第三BNG为备用网关的用户设备而言,可以利用第二网段为其分配IP地址,其中,第一网段、第二网段和第三网段互不相同。对于这种情况,第一BNG的BNG CP还可以为第二用户设备IP地址。在一个示例中,第一BNG的BNG CP可以接收来自于第二用户设备的第二消息,并从第二网段中确定为第二用户设备分配的IP地址。第一BNG的BNG CP确定为第二用户设备分配的IP地址之后,可以将第二用户设备的IP地址发送给第二用户设备。
关于第一BNG的BNG CP接收来自于第二用户设备的第二消息的具体实现,其原理与第一BNG的BNG CP接收来自于第一用户设备的第一消息的实现原理类似,故而第一BNG的BNG CP接收来自于第二用户设备的第二消息的具体实现部分,可以参考上文对于S101的描述部分,此处不再详述。
第一BNG的BNG CP从第二网段中确定为第二用户设备分配的IP地址之后,可以经由第一BNG将第二用户设备的IP地址发送给第二用户设备。换言之,虚拟BNG CP模块可以将第二用户设备的IP地址发送给第一BNG,第一BNG接收到第二用户设备的IP地址之后,可以将第二用户设备的IP地址发送给第二用户设备。
另外,第一BNG还可以将对应第二网段路由作为达到第二用户设备的主用路由发布给其它网络设备,以便于其它网络设备利用该路由向第二用户设备发送数据。另外,第三BNG可以将对应第二网段的路由作为到达第二用户设备的备用路由发布给其它网络设备。
以上对本申请实施例提供的接入控制方法进行了介绍,接下来,结合具体应用场景,介绍本申请实施例提供的方法。
参见图4,该图为本申请实施例提供的一个示例性应用场景示意图。在图4所示的场景中,CU分离,vBNG CP模块401运行在网络管理设备上。vBNG CP模块401对应多个BNG,如图4所示,vBNG CP模块401对应BNG 402、BNG 403和BNG 404。
在图4所示的场景中,BNG 402和BNG 403互为主备关系,BNG 402和BNG 404互为主备关系。vBNG CP模块401中预先存储如下表1所示的对应关系。
表1
主用网关 备用网关 网段
BNG 402 BNG 403 网段1
BNG 402 BNG 404 网段2
BNG 403 BNG 402 网段3
关于表1,需要说明的是,网段1用于为以BNG 402为主用网关、BNG 403为备用网关接入网络的用户设备分配IP地址;网段2用于为以BNG 402为主用网关、BNG 404为备用网关接入网络的用户设备分配IP地址;网段3用于为以BNG 403为主用网关、BNG 404为备用网关接入网络的用户设备分配IP地址。
vBNG CP模块401可以执行本申请以上实施例提供的接入控制方法,为通过BNG 402 或者BNG 403接入网络的用户设备分配IP地址。当vBNG CP模块401可以执行本申请以上实施例提供的接入控制方法时,BNG 402可以对应以上实施例中的第一BNG,BNG 403可以对应以上实施例中的第二BNG,BNG 404可以对应以上实施例中的第三BNG。网段1可以对应于以上实施例中的第一网段,网段2可以对应以上实施例中的第二网段,网段3可以对应以上实施例中的第三网段。
基于以上实施例提供的接入控制方法,本申请实施例还提供了对应的装置,以下结合附图介绍该装置。
参见图5,该图为本申请实施例提供的一种接入控制装置的结构示意图。图5所示的接入控制装置500,例如可以应用于BNG CP,用于执行以上方法实施例中由BNG CP执行的接入控制方法。如图5所示,所述接入控制装置500包括:接收单元501、确定单元502和发送单元503。
接收单元501,用于接收来自于第一用户设备的第一消息,所述第一消息用于请求所述第一用户设备接入网络,所述第一用户设备接入网络的主用网关为第一BNG,所述第一用户设备接入网络的备用网关为第二BNG。
确定单元502,用于根据所述第一消息,从第一网段中确定为所述第一用户设备分配的互联网协议IP地址,所述第一网段用于为以第一BNG为主用网关、第二BNG为备用网关接入网络的用户设备分配IP地址,并且,所述第一网段不用于为以所述第一BNG为备用网关、且以所述第二BNG为主用网关的用户设备分配IP地址。
发送单元503,用于将所述第一用户设备的IP地址发送给所述第一用户设备。
在一种实现方式中,所述接收单元501,还用于接收来自于第二用户设备的第二消息,所述第二消息用于请求所述第二用户设备接入网络,所述第二用户设备接入网络的主用网关为所述第一BNG,所述第二用户设备的接入网络的备用网关为第三BNG。
所述确定单元502,还用于根据所述第二消息,从第二网段中确定为所述第二用户设备分配的IP地址,所述第二网段用于为以所述第一BNG为主用网关、所述第三BNG为备用网关接入网络的用户设备分配IP地址,所述第一网段与所述第二网段不同。
所述发送单元503,还用于将所述第二用户设备的IP地址发送给所述第二用户设备。
在一种实现方式中,所述BNG CP为虚拟BNG CP模块,或者,所述BNG CP运行在所述第一BNG上。
在一种实现方式中,当所述BNG CP为虚拟BNG CP模块时,
所述接收单元501,还用于接收来自于第三用户设备的第三消息,所述第三消息用于请求所述第三用户接入网络,所述第三用户设备接入网络的主用BNG为所述第二BNG,所述第三用户设备接入网络的备用BNG为所述第一BNG。
所述确定单元502,还用于根据所述第三消息,从第三网段中确定为所述第三用户设备分配的IP地址,所述第三网段用于为以所述第二BNG为主用网关、且以所述第一BNG为备用网关接入网络的用户设备分配IP地址,所述第一网段、第二网段和所述第三网段各不相同,所述第二网段用于为以所述第一BNG为主用网关、且以所述第三BNG为备用网关接入网络的用户设备分配IP地址。
所述发送单元503,还用于将所述第三用户设备的IP地址发送给所述第三用户设备。
在一种实现方式中,所述装置还包括:获取单元。
所述获取单元用于获取主用网关、备用网关和网段之间的对应关系,所述对应关系包括以下一项或者多项:
所述第一BNG、所述第二BNG和所述第一网段之间的对应关系;以及,
所述第一BNG、所述第三BNG和所述第二网段之间的对应关系;以及,
所述第二BNG、所述第一BNG和所述第三网段之间的对应关系。
在一种实现方式中,当所述BNG CP为虚拟BNG CP模块时,所述发送单元503用于:
将所述第一用户设备的IP地址经由所述第一BNG发送给所述第一用户设备。
在一种实现方式中,当所述BNG CP运行在所述第一BNG上时,所述发送单元503,还用于:
将对应所述第一网段的路由作为到达所述第一用户设备的主用路由向其它网络设备发布,所述对应所述第一网段的路由为经过所述第一BNG到达所述第一用户设备的路由。
由于所述装置500是与以上方法实施例提供的路由处理方法对应的装置,所述装置500的各个单元的具体实现,均与以上方法实施例为同一构思,因此,关于所述装置500的各个单元的具体实现,可以参考以上方法实施例对于接入控制方法的描述部分,此处不再赘述。
需要说明的是,前述提及的接入控制装置500,其硬件结构可以为如图6所示的结构,图6为本申请实施例提供的一种设备的结构示意图。
请参阅图6所示,设备600包括:处理器610、通信接口620和和存储器630。其中设备600中的处理器610的数量可以一个或多个,图6中以一个处理器为例。本申请实施例中,处理器610、通信接口620和存储器630可通过总线系统或其它方式连接,其中,图6中以通过总线系统640连接为例。
处理器610可以是中央处理器(central processing unit,CPU),网络处理器(network processor,NP)或者CPU和NP的组合。处理器610还可以进一步包括硬件芯片。上述硬件芯片可以是专用集成电路(application-specific integrated circuit,ASIC),可编程逻辑器件(programmable logic device,PLD)或其组合。上述PLD可以是复杂可编程逻辑器件(complex programmable logic device,CPLD),现场可编程逻辑门阵列(field-programmable gate array,FPGA),通用阵列逻辑(generic array logic,GAL)或其任意组合。
存储器630可以包括易失性存储器(英文:volatile memory),例如随机存取存储器(random-access memory,RAM);存储器630也可以包括非易失性存储器(英文:non-volatile memory),例如快闪存储器(英文:flash memory),硬盘(hard disk drive,HDD)或固态硬盘(solid-state drive,SSD);存储器630还可以包括上述种类的存储器的组合。存储器630例如可以存储前述主用网关、备用网关和网段之间的对应关系。
可选地,存储器630存储有操作系统和程序、可执行模块或者数据结构,或者它们的子集,或者它们的扩展集,其中,程序可包括各种操作指令,用于实现各种操作。操作系统可包括各种系统程序,用于实现各种基础业务以及处理基于硬件的任务。处理器610可 以读取存储器630中的程序,实现本申请实施例提供的接入控制方法。
总线系统640可以是外设部件互连标准(peripheral component interconnect,PCI)总线或扩展工业标准结构(extended industry standard architecture,EISA)总线等。总线系统640可以分为地址总线、数据总线、控制总线等。为便于表示,图6中仅用一条粗线表示,但并不表示仅有一根总线或一种类型的总线。
本申请实施例还提供了一种计算机可读存储介质,包括指令或计算机程序,当其在计算机上运行时,使得计算机执行以上实施例提供的接入控制方法。
本申请的说明书和权利要求书及上述附图中的术语“第一”、“第二”、“第三”、“第四”等(如果存在)是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。应该理解这样使用的数据在适当情况下可以互换,以便这里描述的实施例能够以除了在这里图示或描述的内容以外的顺序实施。此外,术语“包括”和“具有”以及他们的任何变形,意图在于覆盖不排他的包含,例如,包含了一系列步骤或单元的过程、方法、系统、产品或设备不必限于清楚地列出的那些步骤或单元,而是可包括没有清楚地列出的或对于这些过程、方法、产品或设备固有的其它步骤或单元。
所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,上述描述的系统,装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。
在本申请所提供的几个实施例中,应该理解到,所揭露的系统,装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,单元的划分,仅仅为一种逻辑业务划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。
作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。
另外,在本申请各个实施例中的各业务单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件业务单元的形式实现。
集成的单元如果以软件业务单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本申请各个实施例方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、磁碟或者光盘等各种可以存储程序代码的介质。
本领域技术人员应该可以意识到,在上述一个或多个示例中,本发明所描述的业务可 以用硬件、软件、固件或它们的任意组合来实现。当使用软件实现时,可以将这些业务存储在计算机可读介质中或者作为计算机可读介质上的一个或多个指令或代码进行传输。计算机可读介质包括计算机存储介质和通信介质,其中通信介质包括便于从一个地方向另一个地方传送计算机程序的任何介质。存储介质可以是通用或专用计算机能够存取的任何可用介质。
以上的具体实施方式,对本发明的目的、技术方案和有益效果进行了进一步详细说明,所应理解的是,以上仅为本发明的具体实施方式而已。
以上,以上实施例仅用以说明本申请的技术方案,而非对其限制;尽管参照前述实施例对本申请进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本申请各实施例技术方案的范围。

Claims (15)

  1. 一种接入控制方法,其特征在于,由宽带网络网关控制平面BNG CP执行,所述方法包括:
    接收来自于第一用户设备的第一消息,所述第一消息用于请求所述第一用户设备接入网络,所述第一用户设备接入网络的主用网关为第一BNG,所述第一用户设备接入网络的备用网关为第二BNG;
    根据所述第一消息,从第一网段中确定为所述第一用户设备分配的互联网协议IP地址,所述第一网段用于为以第一BNG为主用网关、第二BNG为备用网关接入网络的用户设备分配IP地址;
    将所述第一用户设备的IP地址发送给所述第一用户设备。
  2. 根据权利要求1所述的方法,其特征在于,所述方法还包括:
    接收来自于第二用户设备的第二消息,所述第二消息用于请求所述第二用户设备接入网络,所述第二用户设备接入网络的主用网关为所述第一BNG,所述第二用户设备的接入网络的备用网关为第三BNG;
    根据所述第二消息,从第二网段中确定为所述第二用户设备分配的IP地址,所述第二网段用于为以所述第一BNG为主用网关、所述第三BNG为备用网关接入网络的用户设备分配IP地址,所述第一网段与所述第二网段不同;
    将所述第二用户设备的IP地址发送给所述第二用户设备。
  3. 根据权利要求1或2所述的方法,其特征在于,所述BNG CP为虚拟BNG CP模块,或者,所述BNG CP运行在所述第一BNG上。
  4. 根据权利要求3所述的方法,其特征在于,当所述BNG CP为虚拟BNG CP模块时,所述方法还包括:
    接收来自于第三用户设备的第三消息,所述第三消息用于请求所述第三用户接入网络,所述第三用户设备接入网络的主用BNG为所述第二BNG,所述第三用户设备接入网络的备用BNG为所述第一BNG;
    根据所述第三消息,从第三网段中确定为所述第三用户设备分配的IP地址,所述第三网段用于为以所述第二BNG为主用网关、且以所述第一BNG为备用网关接入网络的用户设备分配IP地址,所述第一网段、第二网段和所述第三网段各不相同,所述第二网段用于为以所述第一BNG为主用网关、且以所述第三BNG为备用网关接入网络的用户设备分配IP地址;
    将所述第三用户设备的IP地址发送给所述第三用户设备。
  5. 根据权利要求1-4任意一项所述的方法,其特征在于,所述方法还包括:
    获取主用网关、备用网关和网段之间的对应关系,所述对应关系包括以下一项或者多项:
    所述第一BNG、所述第二BNG和所述第一网段之间的对应关系;以及,
    所述第一BNG、所述第三BNG和所述第二网段之间的对应关系;以及,
    所述第二BNG、所述第一BNG和所述第三网段之间的对应关系。
  6. 根据权利要求3所述的方法,其特征在于,当所述BNG CP为虚拟BNG CP模块时,所述将所述第一用户设备的IP地址发送给所述第一用户设备,包括:
    将所述第一用户设备的IP地址经由所述第一BNG发送给所述第一用户设备。
  7. 根据权利要求3所述的方法,其特征在于,当所述BNG CP运行在所述第一BNG上时,所述方法还包括:
    将对应所述第一网段的路由作为到达所述第一用户设备的主用路由向其它网络设备发布,所述对应所述第一网段的路由为经过所述第一BNG到达所述第一用户设备的路由。
  8. 一种接入控制装置,其特征在于,应用于宽带网络网关控制平面BNG CP,所述装置包括:
    接收单元,用于接收来自于第一用户设备的第一消息,所述第一消息用于请求所述第一用户设备接入网络,所述第一用户设备接入网络的主用网关为第一BNG,所述第一用户设备接入网络的备用网关为第二BNG;
    确定单元,用于根据所述第一消息,从第一网段中确定为所述第一用户设备分配的互联网协议IP地址,所述第一网段用于为以第一BNG为主用网关、第二BNG为备用网关接入网络的用户设备分配IP地址,并且,所述第一网段不用于为以所述第一BNG为备用网关、且以所述第二BNG为主用网关的用户设备分配IP地址;
    发送单元,用于将所述第一用户设备的IP地址发送给所述第一用户设备。
  9. 根据权利要求8所述的装置,其特征在于,
    所述接收单元,还用于接收来自于第二用户设备的第二消息,所述第二消息用于请求所述第二用户设备接入网络,所述第二用户设备接入网络的主用网关为所述第一BNG,所述第二用户设备的接入网络的备用网关为第三BNG;
    所述确定单元,还用于根据所述第二消息,从第二网段中确定为所述第二用户设备分配的IP地址,所述第二网段用于为以所述第一BNG为主用网关、所述第三BNG为备用网关接入网络的用户设备分配IP地址,所述第一网段与所述第二网段不同;
    所述发送单元,还用于将所述第二用户设备的IP地址发送给所述第二用户设备。
  10. 根据权利要求8或9所述的装置,其特征在于,所述BNG CP为虚拟BNG CP模块,或者,所述BNG CP运行在所述第一BNG上。
  11. 根据权利要求10所述的装置,其特征在于,当所述BNG CP为虚拟BNG CP模块时,
    所述接收单元,还用于接收来自于第三用户设备的第三消息,所述第三消息用于请求所述第三用户接入网络,所述第三用户设备接入网络的主用BNG为所述第二BNG,所述第三用户设备接入网络的备用BNG为所述第一BNG;
    所述确定单元,还用于根据所述第三消息,从第三网段中确定为所述第三用户设备分配的IP地址,所述第三网段用于为以所述第二BNG为主用网关、且以所述第一BNG为备用网关接入网络的用户设备分配IP地址,所述第一网段、第二网段和所述第三网段各不相同,所述第二网段用于为以所述第一BNG为主用网关、且以所述第三BNG为备用网关接入网络的用户设备分配IP地址;
    所述发送单元,还用于将所述第三用户设备的IP地址发送给所述第三用户设备。
  12. 根据权利要求8-11任意一项所述的装置,其特征在于,所述装置还包括:
    获取单元,用于获取主用网关、备用网关和网段之间的对应关系,所述对应关系包括以下一项或者多项:
    所述第一BNG、所述第二BNG和所述第一网段之间的对应关系;以及,
    所述第一BNG、所述第三BNG和所述第二网段之间的对应关系;以及,
    所述第二BNG、所述第一BNG和所述第三网段之间的对应关系。
  13. 根据权利要求10所述的装置,其特征在于,当所述BNG CP为虚拟BNG CP模块时,所述发送单元,用于:
    将所述第一用户设备的IP地址经由所述第一BNG发送给所述第一用户设备。
  14. 根据权利要求10所述的装置,其特征在于,当所述BNG CP运行在所述第一BNG上时,所述发送单元,还用于:
    将对应所述第一网段的路由作为到达所述第一用户设备的主用路由向其它网络设备发布,所述对应所述第一网段的路由为经过所述第一BNG到达所述第一用户设备的路由。
  15. 一种计算机可读存储介质,其特征在于,包括指令或计算机程序,当其在计算机上运行时,使得计算机执行以上权利要求1-7任意一项所述的方法。
PCT/CN2021/112662 2020-08-19 2021-08-16 一种接入控制方法及装置 WO2022037509A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP21857604.9A EP4199430A4 (en) 2020-08-19 2021-08-16 ACCESS CONTROL METHOD AND APPARATUS
US18/170,694 US20230198796A1 (en) 2020-08-19 2023-02-17 Access control method and apparatus

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202010837047.9 2020-08-19
CN202010837047.9A CN114079586A (zh) 2020-08-19 2020-08-19 一种接入控制方法及装置

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US18/170,694 Continuation US20230198796A1 (en) 2020-08-19 2023-02-17 Access control method and apparatus

Publications (1)

Publication Number Publication Date
WO2022037509A1 true WO2022037509A1 (zh) 2022-02-24

Family

ID=80282669

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2021/112662 WO2022037509A1 (zh) 2020-08-19 2021-08-16 一种接入控制方法及装置

Country Status (4)

Country Link
US (1) US20230198796A1 (zh)
EP (1) EP4199430A4 (zh)
CN (1) CN114079586A (zh)
WO (1) WO2022037509A1 (zh)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102215158A (zh) * 2010-04-08 2011-10-12 杭州华三通信技术有限公司 实现vrrp流量传输的方法和路由设备
CN102340421A (zh) * 2007-11-22 2012-02-01 华为技术有限公司 网关的管理方法、地址分配的方法及装置、系统
CN102651711A (zh) * 2012-04-28 2012-08-29 华为技术有限公司 一种建立和使用浮动网段的方法、装置和系统
CN103036701A (zh) * 2012-04-01 2013-04-10 浙江宇视科技有限公司 一种跨网段的n+1备用方法及装置
US20180062879A1 (en) * 2016-08-31 2018-03-01 Cooper Technologies Company Systems and methods for increasing network access capacity

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107786613B (zh) * 2016-08-30 2020-05-12 新华三技术有限公司 宽带远程接入服务器bras转发实现方法和装置
CN114363285A (zh) * 2020-09-28 2022-04-15 华为技术有限公司 地址管理的方法、装置及系统

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102340421A (zh) * 2007-11-22 2012-02-01 华为技术有限公司 网关的管理方法、地址分配的方法及装置、系统
CN102215158A (zh) * 2010-04-08 2011-10-12 杭州华三通信技术有限公司 实现vrrp流量传输的方法和路由设备
CN103036701A (zh) * 2012-04-01 2013-04-10 浙江宇视科技有限公司 一种跨网段的n+1备用方法及装置
CN102651711A (zh) * 2012-04-28 2012-08-29 华为技术有限公司 一种建立和使用浮动网段的方法、装置和系统
US20180062879A1 (en) * 2016-08-31 2018-03-01 Cooper Technologies Company Systems and methods for increasing network access capacity

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP4199430A4

Also Published As

Publication number Publication date
EP4199430A1 (en) 2023-06-21
US20230198796A1 (en) 2023-06-22
CN114079586A (zh) 2022-02-22
EP4199430A4 (en) 2024-03-06

Similar Documents

Publication Publication Date Title
CN116057910B (zh) 虚拟私有云通信及配置方法以及相关装置
CN111460460B (zh) 任务访问方法、装置、代理服务器及机器可读存储介质
EP2499787B1 (en) Smart client routing
CN111865621B (zh) 接入网关的方法及装置
US8289968B1 (en) Distributed network address translation in computer networks
US20130024553A1 (en) Location independent dynamic IP address assignment
WO2020186925A1 (zh) 一种数据传输的方法和计算机系统
US8458303B2 (en) Utilizing a gateway for the assignment of internet protocol addresses to client devices in a shared subset
WO2016095561A1 (zh) 一种地址分配方法、cgn设备及cgn双主系统
EP3614650B1 (en) Separation of forwarding plane and control plane of cgn
US8706908B2 (en) System, method and apparatus for media access control (MAC) address proxying
CN107547665B (zh) 一种dhcp地址分配的方法、设备及系统
WO2020108438A1 (zh) 一种接入系统、方法及装置
CN110012118B (zh) 一种提供网络地址转换nat服务的方法及控制器
WO2023221708A1 (zh) Pdn拨号及配置方法、系统、装置、设备及存储介质
WO2022037509A1 (zh) 一种接入控制方法及装置
WO2024000975A1 (zh) 一种会话建立系统、方法、电子设备及存储介质
CN114124737B (zh) 一种控制用户设备接入网络的方法及装置
CN111556176B (zh) 一种数据包转发控制系统及方法
US10862849B2 (en) Address resolution system
CN114765601A (zh) 一种地址前缀获取方法及装置
US20240163217A1 (en) Apparatuses, methods and non-transitory computer-readable storage mediums for network access to residential gateways
CN111917858B (zh) 一种远程管理系统、方法、装置及服务器
WO2022012383A1 (zh) 一种报文传输的方法、装置、系统及存储介质
WO2022089027A1 (zh) 发送报文的方法、装置、系统及存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21857604

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 2021857604

Country of ref document: EP

Effective date: 20230316